Open Framework · Public Beta

Sovereign cloud architectures for a multi-cloud reality

WAF++ is an open framework for everyone who wants to design cloud architectures intentionally, securely, and vendor-neutral — built from real engineering, not marketing.

Trusted by
AppSec SRE Platform Cloud Engineering
WAF++ · Risk Intelligence
Signal → Decision → Policy
69 % of breaches involve misconfiguration
68 % rank misconfiguration as top risk
5+ M USD impact of non-compliance
7 pillars covering the full stack
wafpass
$ wafpass check ./infra/
PASS [SEC-001] Encryption at rest enabled
PASS [SOV-003] Data residency: eu-central-1
FAIL [COST-002] Untagged resources detected
SKIP [PERF-001] Load balancer: no config
2 pass · 1 fail · 1 skip — 4 controls checked
WAFPASS · CLI TOOL

Validate your Terraform against WAF++ Beta

WAFPass automatically checks your infrastructure-as-code against WAF++ controls — static analysis, no cloud access required.

Static analysis on .tf files

Runs entirely on your Terraform source. No cloud credentials needed, no API calls — safe for CI and local dev.

All 7 pillars covered

Controls mapped across Security, Cost, Performance, Reliability, Ops, Sustainability, and Sovereign.

PDF compliance reports

Export shareable reports with findings, severity, and remediation guidance. Maps to GDPR, BSI, ISO 27001, SOC 2.

CI/CD ready

Native GitHub Actions, GitLab CI, and pre-commit hook integrations. Block merges on policy violations.

✓ PASS ✗ FAIL – SKIP
wafpass — ./infrastructure/
$ wafpass check ./infrastructure/
Checking 47 controls across 7 pillars...
PASS SEC-001Encryption at rest enabled (S3, RDS)
PASS SEC-007MFA required for IAM users
FAIL SEC-012Public S3 bucket: logs-bucket
PASS SOV-001Data residency: eu-central-1 ✓
SKIP SOV-004Cross-border data flow (no config)
FAIL COST-00212 untagged EC2 resources found
PASS COST-005Reserved instance coverage: 78%
SKIP PERF-001Load balancer check: no ALB found
Results: 4 pass · 2 fail · 2 skip — PDF report ready
PRINCIPLES

Built for the real world

No vendor marketing, no lock-in — just engineering-first principles shaped by real cloud projects.

01
Neutral & Open

WAF++ is not tied to AWS, Azure, or GCP. It applies across all cloud providers and is fully open — MIT licensed, community-governed, and free to use forever.

02
Engineering-first

Every control, every principle is rooted in real project experience. No theoretical frameworks — just patterns that survive contact with production environments.

03
Fully Traceable

Every decision is documented, every change is reviewed. RFC-driven governance means you always know why a rule exists — and can challenge it if reality disagrees.

References

"WAF++ provides a stable foundation for digital applications and shows how technical precision and design sensitivity can be successfully combined. The chosen color palette — with a solid, modern base tone and a fresh accent — conveys reliability while creating a visual identity that is both scalable and appealing."

Lydia Hundsdörfer
Lydia Hundsdörfer
Project & Partner Manager Vogel IT

"WAF++ has great potential to become the perfect answer to real-world everyday questions from the technology, cloud & developer community. With increasing dynamics and the tension between the drive for innovation, technology overload, and sovereignty, companies and technology experts are under growing pressure and have so far found mostly fragmented or sales-driven answers. WAF++ starts a movement that brings together genuine hands-on expertise from the field — and can evolve it further."

Maximilian Hille
Maximilian Hille
Cloud Analyst
GET STARTED

Ready to design with intention?

Start with the fundamentals, validate your Terraform with WAFPass, and build cloud architectures that are secure, sovereign, and built to last.

GDPR compliant SOC 2 ready HIPAA PIPEDA BSI C5 ISO 27001